Configuring Bypass Mode; Configuring Interface Notifications - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Configuring Interface Notifications

Configuring Bypass Mode

Use the bypass-option command in the service interface submode to configure bypass mode.
The following options apply:
Log in to the CLI using an account with administrator privileges.
Step 1
Enter interface submode:
Step 2
sensor# configure terminal
sensor(config)# service interface
Step 3
Configure bypass mode:
sensor(config-int)# bypass-mode off
Step 4
Verify the settings:
sensor(config-int)# show settings
-----------------------------------------------
bypass-mode: off default: auto
interface-notifications
-----------------------------------------------
-----------------------------------------------
sensor(config-int)#
Exit interface submode:
Step 5
sensor(config-int)# exit
Apply Changes:?[yes]:
Press Enter to apply the changes or type
Step 6
Configuring Interface Notifications
You can configure the sensor to monitor the flow of packets across an interface and send notification if
that flow changes (starts/stops) during a specified interval. You can configure the missed packet
threshold within a specific notification interval and also configure the interface idle delay before a status
event is reported.
Use the interface-notifications command in the service interface submode to configure traffic
notifications.
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
5-10
off—Turns off inline bypassing. Packet inspection will be performed on inline data traffic. However,
inline traffic will be interrupted if the analysis engine is stopped.
on—Turns on inline bypassing. No packet inspection will be performed on the traffic. Inline traffic
will continue to flow even if the analysis engine is stopped.
auto—Automatically begins bypassing inline packet inspection if the analysis engine stops
processing packets. This prevents data interruption on inline interfaces. This is the default.
missed-percentage-threshold: 0 percent <defaulted>
notification-interval: 30 seconds <defaulted>
idle-interface-delay: 30 seconds <defaulted>
to discard them.
no
Chapter 5
Configuring Interfaces
78-16527-01

Advertisement

Table of Contents
loading

Table of Contents